Live data from Hacker News

'Shimmers' are the newest tool for stealing credit card info

cbc.ca

61–70 of 88 posts

Re: 'Shimmers' are the newest tool for stealing credit card info

#62

Earlier quoted context omitted.

They have the new readers but they don't use them

Notable the article is from Canada. Here in Canada virtually all retailers have been using chip+pin for a good number of years now. The same in the UK, where they have been using it for over 10 years. Retailers have to use chip+pin to avoid fraud liability. In the USA, however, a lot of retailers were still using signatures up until a year or two. It seems to be only in the last year that retailers are starting to mo…

They are not moving to chip and pin, but chip and signature: very different.

Now, the internet being a bigger share of retail every year, chip and pin is not an improvement: what we need is 2FA across the board. You have my CC number? Great. Without my 2FA secret, you won't be able to charge me anyway.

This 2FA beats a pin, and would make payment fraud so much smaller, it'd become a minor thing, but good luck finding a bank in the US offering such feature for all charges.

Re: 'Shimmers' are the newest tool for stealing credit card info

#63
post #60

Earlier quoted context omitted.

It's not.

Then is the article inaccurate when it says, "Once installed, the microchips on the shimmer record information from chip cards, including the PIN."?

I don't know the details, but there are probably many possible ways to get the PIN, since it's getting entered right then and there. Smartcard is a small computer, but the connection to it from terminal is probably not that secure and can be read somehow, side-channels or directly.

The card decides if the PIN is correct, but it might be possible to record all the PINs that were tried.

Re: 'Shimmers' are the newest tool for stealing credit card info

#64
post #6

Krebs has a post on this as well: https://krebsonsecurity.com/2017/01/atm-shimmers-target-chip... “The only way for this attack to be successful is if a [bank card] issuer neglects to check the CVV when authorizing a transaction,”

I have not had the largest confidence in banks abilities to understand security. I've personally dealt with: 1) 'Two factor auth is on, you have to answer two security questions to access your account!' 2) 'Your password is limited to exactly 8 characters ... for security' 3) 'Oh, we now support SMS two factor auth' -- 4 months in, I've received 1 SMS challenge 4) 'You don't want a chip card, they are more hassle' 5)…

> You don't want a chip card, they are more hassle

As a consumer, I am indemnified by my bank, per Regulation E, against fraud from swipes. I get no benefit from the slower chip + sig system.

Re: 'Shimmers' are the newest tool for stealing credit card info

#65
post #62

Earlier quoted context omitted.

Notable the article is from Canada. Here in Canada virtually all retailers have been using chip+pin for a good number of years now. The same in the UK, where they have been using it for over 10 years. Retailers have to use chip+pin to avoid fraud liability. In the USA, however, a lot of retailers were still using signatures up until a year or two. It seems to be only in the last year that retailers are starting to mo…

They are not moving to chip and pin, but chip and signature: very different. Now, the internet being a bigger share of retail every year, chip and pin is not an improvement: what we need is 2FA across the board. You have my CC number? Great. Without my 2FA secret, you won't be able to charge me anyway. This 2FA beats a pin, and would make payment fraud so much smaller, it'd become a minor thing, but good luck finding…

>They are not moving to chip and pin, but chip and signature: very different.

No, that's not quite true. They are moving to chip+pin, but some card issuers are not currently issuing PINs. However the machines themselves fully support chip+pin (and I can confirm this, as most places in the USA now require me to enter a PIN for my card).

http://www.creditcards.com/credit-card-news/emv-faq-chip-car...

Re: 'Shimmers' are the newest tool for stealing credit card info

#66
post #5

Earlier quoted context omitted.

Not all terminals in the States support chip functionality, so for the time being chip & pin cards here still have normal mag strips and can be run as older, regular cards - the mag strips can still be read/stolen & used.

IMO it's super dumb that we're going through the whole business of replacing card readers to get chip support but NOT getting pin requirements. I've had a few CCs stolen from my mailbox (apartment with a large shared mailbox with simple padlocks). The new chip-only doesn't protect against this at all. MasterCard SecureCode was also a step in the right direction IMO, but the adoption rate seems very low. Basically, I…

How were thieves able to activate cards stolen from your mail box?

Re: 'Shimmers' are the newest tool for stealing credit card info

#67
post #62

Earlier quoted context omitted.

They are not moving to chip and pin, but chip and signature: very different. Now, the internet being a bigger share of retail every year, chip and pin is not an improvement: what we need is 2FA across the board. You have my CC number? Great. Without my 2FA secret, you won't be able to charge me anyway. This 2FA beats a pin, and would make payment fraud so much smaller, it'd become a minor thing, but good luck finding…

>They are not moving to chip and pin, but chip and signature: very different. No, that's not quite true. They are moving to chip+pin, but some card issuers are not currently issuing PINs. However the machines themselves fully support chip+pin (and I can confirm this, as most places in the USA now require me to enter a PIN for my card). http://www.creditcards.com/credit-card-news/emv-faq-chip-car...

And even if you want a PIN for your card, the credit card company doesn't know how to give it to you. Last summer, before I went to a conference in Canada, I called all 3 of my credit cards's customer service departments trying to get a PIN (American Express, Discover, MasterCard), and none of them would issue a PIN for my chip'ed card. I don't think any of the CSRs even knew what I was talking about. One even told me that PIN's were "just for debit cards". Sigh.

Re: 'Shimmers' are the newest tool for stealing credit card info

#68
post #62

Earlier quoted context omitted.

They are not moving to chip and pin, but chip and signature: very different. Now, the internet being a bigger share of retail every year, chip and pin is not an improvement: what we need is 2FA across the board. You have my CC number? Great. Without my 2FA secret, you won't be able to charge me anyway. This 2FA beats a pin, and would make payment fraud so much smaller, it'd become a minor thing, but good luck finding…

>They are not moving to chip and pin, but chip and signature: very different. No, that's not quite true. They are moving to chip+pin, but some card issuers are not currently issuing PINs. However the machines themselves fully support chip+pin (and I can confirm this, as most places in the USA now require me to enter a PIN for my card). http://www.creditcards.com/credit-card-news/emv-faq-chip-car...

I use a debit card with a pin and some retailers still do a signature transaction for me without any choice.

Re: 'Shimmers' are the newest tool for stealing credit card info

#69

Earlier quoted context omitted.

From the issuer side, the solution to remove this risk is simple (and I believe I was told it in an EMV implementation seminar 10 years ago): If the incoming transaction lists that the terminal is chip&pin capable, so you'd simply automatically reject a magstripe transaction with a code that should result in POS showing "please insert card in the chip reader"; If the incoming transaction lists that the terminal is no…

If you try to swipe a chip card then yes, the terminal will reject the swipe and tell you to insert the chip. If your chip fails three successive tries, the terminal will accept a mag swipe instead. I don't know if this is true everywhere but I have seen it in multiple retailers across the US. Point is, if attackers are cloning mag cards from chip data, those cards can still be used in chip terminals.

New Zealand chip card machines does the same but I think it only need two chip read failures before it falls back to swiping using the magnetic strip.

Re: 'Shimmers' are the newest tool for stealing credit card info

#70
post #58
post #4

I'm having a surprising amount of trouble finding this information online: does the "chip" include some functionality (maybe called iCVV or dCVV) that allows it to individually "sign" transactions using internal secret keys, or does it not? This was my understanding of why the new system was supposed to be safer. If the answer is yes, secret keys that never leave the chip are used to sign each transaction and the sig…

They probably just steal data from the magnetic stripe + detect key-presses somehow for a PIN.

Yeah, this is what I automatically assumed.
Post reply on HN